Your DORA questions answered – Business resilience more broadly
This fifth of a series of articles covering a practical session organised by Ashurst focuses on business resilience questions connected to DORA.
Rule Overview
Jurisdiction: European Union
Regulator: ESMA
Topic: Business Continuity, Resilience
EUR-Lex (EU) 2024/1773DORA Article 30(2)-(3) outlines the minimum elements that must be included in any contractual arrangements on the use of ICT services:
The policy needs to specify that the contractual arrangements must include:
The final responsibility for inspection, audit and testing rests with the financial entity who can employ the following in order to carry these out:
The financial entity cannot only rely on third party certification or reports supplied by the ICT third-party service provider and these can only be used if the financial entity:
Any material changes to these arrangements must be:
By all parties
Your DORA questions answered – Business resilience more broadly
This fifth of a series of articles covering a practical session organised by Ashurst focuses on business resilience questions connected to DORA.
Thomas Hyrkiel 3 min read
Your DORA questions answered – CIFs
This third of a series of six articles covering a practical session organised by Ashurst focuses on critical or important functions.
Thomas Hyrkiel 4 min read
Your DORA questions answered – Extraterritoriality and interaction with existing rules
This last of a series of six articles covering a practical session organised by Ashurst focuses on how DORA will interact with existing rules as well as its extraterritorial effects.
Thomas Hyrkiel 3 min read
As advances in AI change the cyber risk landscape, Finanstilsynet lists measures for firms to increase preparedness and strengthen governance.
Research reveals vulnerability in legacy telecoms standards that is being overlooked by finance firms.
Discussion on this panel at XLOD Global centered on interpreting and implementing evolving expectations on non-financial risk.
New course aims to help SMEs remain compliant in a complex regulatory landscape.
The Action Plan does not create new legal obligations but sets out steps for operationalizing the AI Act, NIS2, DORA, and the Cyber Resilience Act.
What financial business leaders can learn from the Roman general.
The ECB has given eurozone banks until October 31, 2026, to submit plans on how they will strengthen governance and resilience against growing AI-enabled cyberthreats.
This article examines the key challenges firms have encountered in their DORA compliance journeys and explores some of the practical solutions.